- [Home](/)
- [Legal](/legal)
- Data processing

Legal

# Data processing

How CubeCRM handles the data your organisation puts into it, and what our data processing agreement commits us to.

- Updated 25/09/2026
- 7 min read
- For customers

## The short version

- You are the controller

We process your data only on your documented instructions, under a data processing agreement that is part of every customer contract.

- Security in the base product

Role-based permissions, single sign-on, an audit log that cannot be edited and encryption come with every subscription, not as an upgrade.

- UK storage, named providers

Databases, files and backups stay in the UK. The providers we use are named, and changes come with 30 days’ notice.

- Your data leaves when you do

Export it whenever you like, in open formats. When a contract ends, you have time to take it, and then it is deleted on a stated timetable.

A summary for convenience. The full text below is what applies.

On this page

- [1Who is responsible for what](#roles)
- [2Our data processing agreement](#data-processing-agreement)
- [3What CubeCRM holds](#what-cubecrm-holds)
- [4Where it is held](#where-it-is-held)
- [5How it is protected](#security)
- [6Services you connect](#connected-services)
- [7Sub-processors](#sub-processors)
- [8Requests from individuals](#requests-from-individuals)
- [9Security incidents](#security-incidents)
- [10When a contract ends](#end-of-contract)

On this page10 sections
- [1Who is responsible for what](#roles)
- [2Our data processing agreement](#data-processing-agreement)
- [3What CubeCRM holds](#what-cubecrm-holds)
- [4Where it is held](#where-it-is-held)
- [5How it is protected](#security)
- [6Services you connect](#connected-services)
- [7Sub-processors](#sub-processors)
- [8Requests from individuals](#requests-from-individuals)
- [9Security incidents](#security-incidents)
- [10When a contract ends](#end-of-contract)

Print or save as PDF[Ask us a question](mailto:hello@cubecrm.co.uk)[All legal documents](/legal)
## 1. Who is responsible for what

When your organisation uses CubeCRM, you decide what data goes into it and what it is used for. You are the controller of that data, and Cube Systems Limited is your processor.

If you hold some of that data as a processor yourself, for example on behalf of one of your own customers, we act as your sub-processor for it, and the commitments on this page cover it in the same way.

Separately, we are a controller for the small amount of data we need to run our own business, such as the details of your account contacts and our billing records. That is covered by our [privacy policy](/legal/privacy-policy).

## 2. Our data processing agreement

Every customer agreement includes a data processing agreement that meets Article 28 of UK GDPR. Under it, we:

- process your data only on your documented instructions, which include using CubeCRM as designed with the configuration you choose, and tell you if we believe an instruction breaks the law;
- make sure everyone with access to it is bound by confidentiality;
- maintain the technical and organisational measures described [below](#security);
- use sub-processors only under written contracts with equivalent obligations, and give you notice before any change;
- help you answer requests from people exercising their rights, and with data protection impact assessments and any consultation with the ICO;
- notify you of a personal data breach affecting your data without undue delay;
- delete or return your data when the contract ends; and
- make available the information you need to demonstrate compliance, and allow for audits, including inspections, by you or an auditor you appoint.

To review the agreement before you sign, email [hello@cubecrm.co.uk](mailto:hello@cubecrm.co.uk) and we will send you a copy.

## 3. What CubeCRM holds

Categories of data held in CubeCRMCategoryExamplesPeopleYour staff who use the system; the contacts at your customers and prospects; people who send you an enquiry through your website or by email; and anyone named in a note, activity, email or case logged against a record.Contacts and accountsContacts and the companies they work for, with job titles, phone numbers, email and postal addresses, relationships between records, and the consent, lawful basis and marketing preferences you record for each contact.Sales recordsLeads and enquiries, deals and opportunities with their stage and value, quotes and proposals with every revision, price lists, forecasts and the notes filed against a record.Activities and correspondenceCalls, meetings, visits, tasks and follow-ups; emails logged from Outlook or Gmail with their attachments; calendar entries; and photographs taken on visits.Service casesCustomer queries, complaints and after-sales issues, with their history, owners, response targets and resolution.Connected-service dataInvoices, balances and payment status, calendar entries, call logs and campaign results exchanged with services you connect, such as your accounting package, email platform or phone system.Account and security recordsUsers, roles and permissions, sign-in history, API access tokens and call logs, and the audit log of every change.CubeCRM does not need special category data to work. Notes, logged emails and case descriptions are free text, and an email can contain anything its sender wrote, so please make sure your team does not record health or other sensitive information unless you have a lawful basis to do so.

## 4. Where it is held

Your data is stored in the United Kingdom:

- application servers, databases and backups in UK data centres operated by Crushed Ice, part of Crushed Ice Group; and
- uploaded files and attachments in Amazon S3, and system email sent through Amazon SES, both in the AWS London region.

None of our sub-processors stores or processes your CubeCRM data outside the UK. Email and calendars synced from Microsoft 365 or Google Workspace also stay in your own tenant, and services you connect hold data under their own terms.

## 5. How it is protected

### Access and permissions

- Role-based permissions down to record and field level, and approval limits on discounts.
- Single sign-on through Microsoft Entra ID or Google Workspace, with your own multi-factor authentication and conditional access policies applied. When someone leaves and their account is disabled, their access to CubeCRM ends with it.
- Your data kept separate from other customers’ data, and access by our staff limited to the people who need it to run and support the service.

### Audit and integrations

- An audit log of every change, recording who changed what and when, which cannot be edited.
- API access through tokens scoped to the endpoints and records an integration needs, revocable individually, with every call logged.
- A separate sandbox environment for integration work, so development never touches live records.

### Encryption and resilience

- Encryption in transit and at rest.
- Encrypted off-site backups held in the UK, with a documented, tested recovery process.
- Continuous, versioned updates, so no customer is left on a release too old to support.

## 6. Services you connect

CubeCRM can connect to services your organisation already uses, including Microsoft 365, Google Workspace, Xero, Sage, QuickBooks, Mailchimp, Website Forms & Enquiries, Telephony & VoIP and Power BI & Reporting. You choose which to connect and what they can access, and you can disconnect them at any time.

Those services are not our sub-processors. You have your own agreement with each of them, and the data they hold is covered by their terms. What each connection is used for is listed on our [sub-processors](/legal/sub-processors#services-you-connect) page.

## 7. Sub-processors

We use a small number of sub-processors, each named on our [sub-processors](/legal/sub-processors) page with what it does, what it processes and where. We give customers at least 30 days’ notice by email before adding or replacing one, and you can object during that period. If we cannot resolve a reasonable objection, you may terminate the affected part of the service.

## 8. Requests from individuals

When someone asks you to exercise their data protection rights, you can find, correct, export and delete the records relating to them in CubeCRM, and we will help you extract anything you cannot export yourself. If a request about your data comes to us directly, we will pass it to you without undue delay and will not answer it ourselves unless you ask us to.

## 9. Security incidents

If we become aware of a personal data breach affecting your data, we will notify your nominated contact without undue delay, and in any event within 48 hours, so that you can meet the 72-hour deadline for reporting to the ICO. We will tell you what happened, the data and people likely to be affected, the likely consequences and what we are doing about it, and keep you updated as we learn more.

## 10. When a contract ends

You can export your data in full at any time in open formats, not only at the end. When a contract ends:

- your system stays available for export for 30 days;
- we then delete your data from live systems within a further 60 days, including the audit log, and confirm in writing when we have; and
- copies in backups expire on their normal rotation within 90 days after that, and are not restored in the meantime.

We keep only what the law requires of us, such as invoices, which our privacy policy covers.

Contact

## Questions about this document

Email us and a person will reply. For anything about data a business holds in its CubeCRM system, please contact that business first, as it decides how the data is used.

[Email us](mailto:hello@cubecrm.co.uk)CompanyCube Systems Limited, trading as CubeCRMCompany number[17220899](https://find-and-update.company-information.service.gov.uk/company/17220899), registered in England and WalesRegistered officeUnit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FPEmail[hello@cubecrm.co.uk](mailto:hello@cubecrm.co.uk)Telephone[01234 672 617](tel:+441234672617)ICO registration[ZC216972](https://ico.org.uk/ESDWebPages/Entry/ZC216972)
## Other legal documents

[Legal overview](/legal)
-
### [Privacy policy](/legal/privacy-policy)

What personal data we collect through this website, our sales and support, and CubeCRM accounts, why we need it, and the rights you have over it.

Updated 25/09/2026

-
### [Cookie policy](/legal/cookies)

This website sets no cookies unless you allow Google Analytics. The CubeCRM application uses one to keep you signed in. The full list, and how to change your mind.

Updated 25/09/2026

-
### [Terms of use](/legal/terms-of-use)

The rules for using this website, including automated and AI access. Subscriptions to CubeCRM are covered by your customer agreement instead.

Updated 25/09/2026

-
### [Sub-processors](/legal/sub-processors)

The third parties that process customer data on our behalf, what each one does, where it does it, and how we tell you about changes.

Updated 25/09/2026

---

**URL:** https://cubecrm.co.uk/legal/data-processing
